ralph-tdd

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Benign in terms of the described capability mapping: the Ralph TDD loop is a coherent autonomous development workflow with testing and mutation-gated QA. However, there are notable supply-chain and runtime-control risks due to reliance on external skill installs (npx) and AFK full-auto modes; these require strict provenance verification, pinning, and runtime sandboxing for safe deployment.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 12:58 AM
Package URL
pkg:socket/skills-sh/jonmumm%2Fskills%2Fralph-tdd%2F@5b0a9ab1a63306a083ddd896e781601c03d2281b